Live data from Hacker News

Should Failing Phish Tests Be a Fireable Offense?

krebsonsecurity.com

181–190 of 357 posts

Re: Should Failing Phish Tests Be a Fireable Offense?

#181

Earlier quoted context omitted.

Sure, that's an explanation for those sorts of jobs, but they aren't usually a target of phishing attempts.

I'm a reasonably well paid software engineer in Silicon Valley, but I don't get a bonus or options of any kind. I suppose my employer to could take vacation days from me or not give me a raise next year, but if they did either of those things because I "failed" a phishing test (where "fail" doesn't even involve giving up any credentials) I would probably be looking for a new job anyway so they might as well fire me.

Forgone bonus was just an example. It could be any sort of penalty or loss of perk, and my question is directed at the stead state equilibrium of the job market, not at behavior given whatever contracts are currently signed. E.g., instead of offering someone $85k, offer them $84k plus a $1k bonus if they avoid phishing attacks. Or give a bonus vacation day to each employee who passes the test. Etc.

Re: Should Failing Phish Tests Be a Fireable Offense?

#182

Earlier quoted context omitted.

I work at a financial company and we have a similar policy around phishing email. Embarrassingly, I failed this once and then created an email rule which filters out the fake Phish. No idea if it gets real Phish.

> Embarrassingly, I failed this once and then created an email rule which filters out the fake Phish. how did it get you, if you don't mind sharing? It seems if someone who works in IT (guessing you do) and is very careful fails it, this is an impossibly high standard to meet. curious how they got you.

> It seems if someone who works in IT and is very careful fails it, this is an impossibly high standard to meet.

It's the same reason you automate things. People make mistakes. It's not about messing up once. It's about always being absolutely positively sure that you aren't making a mistake.

If you've ever clicked on a link from an email, you are vulnerable.

Re: Should Failing Phish Tests Be a Fireable Offense?

#183

Earlier quoted context omitted.

I recently failed a suspicious email / phishing test for the first time, and I am also one of those people who never thought it would happen to me... The email was a newsletter I didn't care about, and the unsubscribe link was (fake) malicious. That one impressed me because it preyed on what is now a pure reflex to click the unsubscribe link.

> a pure reflex to click the unsubscribe link. That's a learned trait. I don't click unsubscribe links; I click "report spam" and "report phishing" button. If only Gmail would let me create filters to automatically mark entire domains as spam though. That would be nice...

The unsubscribe link is more effective at stopping unwanted emails.

I automatically unsubscribe people who mark email as spam but lots of marketers dont do that so you will still receive emails.

Most legitimate companies will respect the unsubscribe links as that is required by law and they invested more infrastructure around that functionality.

I wouldn't click on links from phishing attempts or emails from sketchy services I never signed up. Anything semi-legit is better handled through the unsubscribe link first.

Re: Should Failing Phish Tests Be a Fireable Offense?

#184
post #95

Earlier quoted context omitted.

With that logic just having your mail client/web mail parse a malicious mail from a nation-state level actor is enough to compromise your machine.

It happens all the time. https://thecoinshark.net/microsoft-email-clients-was-hacked-...

From the original article which that page links to [0]:

The breach centered around a hacker getting hold of a Microsoft customer support worker’s login credentials; from there, the hacker could dive into the content of any non-corporate Outlook, Hotmail, or MSN account

This is a security concern for any mail that an administrator can read, although it isn't at the same level as being compromised just through parsing an email.

[0] https://www.vice.com/en_us/article/xwndwn/microsoft-outlook-...

Re: Should Failing Phish Tests Be a Fireable Offense?

#185
post #58

I worked for a defense contractor that had a 3 strikes policy for security violations. Failing the phishing emails was a strike. Other breaches of security policy (like getting caught letting someone tailgate you in) could be strikes too. You got fired at 3. Nobody thought this was unreasonable. Part of your job when you work in defense or finance is giving a sufficient number of fucks about things that people in oth…

I actually like the idea of having consequences for allowing tailgating, assuming the company cares about it. Maybe not firing, at least right away, or if you get tricked/someone sneaks in behind you, but put some teeth in the policy and actually enforce it. If the company just says "don't do it" there is still social pressure to be polite and not slam the door in someone's face. But if there are consequences that ev…

The company has a one strike policy for letting someone use your badge, or letting someone tailgate.

They also have people who go out and try to tailgate, and say they left their badge on the other side of the door and ask if you can badge them in, or let them borrow your badge to get theirs. If you help, they walk in and get security and HR and you're done.

Re: Should Failing Phish Tests Be a Fireable Offense?

#186

I might consider this - if my employer gave me tools to deal with looking at email headers, etc etc etc. That means iff I have to use Outlook/Exchange, and nobody will tell me what the external SMTP server IP address is (and other information) this is unreasonable. I've had two different large, corporate employers do the phishing training thing. I've failed occasionally at both of them. You can make a phish as close…

>That is, I'm just not going to look for, or even open, emails. How long do you think most people could get away with that without being fired? I'd guess I'd last about a week at most.

I don’t think parent means that in the absolute sense, just the relative sense. As in, not even opening emails where the sender or subject suggests spam.

I’ve almost direct-deleted an email like this, but it turned out that the sender got married and changed their name.

Re: Should Failing Phish Tests Be a Fireable Offense?

#187

I have a client in the banking industry who performed these tests. Everyone failed. I'm not sure if they ran them again but there's a point where you need to sit someone down and explain how serious the situation is. If they still don't get it, you should probably fire them or transfer them to a department that isn't vulnerable.

Did they run the tests without training first?

What’s the point?

If Security/IT is so dense that they see any value in testing before training, we’ve already identified a problem: culture or a “our employees are too smart for this issue”.

Re: Should Failing Phish Tests Be a Fireable Offense?

#188

Earlier quoted context omitted.

I rather like my buildings' set up for this— We have passcarded doors and then inside we have gates like many subway stations do that are timed only long enough for one person to pass through. So I can hold the door open for someone on the way in—especially if they have their badge out— but there's nothing I can do about those giant plexi gates once inside. They have to swipe.

The city of Toronto would like to hear from you. Our Subway turnstiles keep breaking. And since they’re entry and exit, there’s many methods to enter by triggering the exit side, from umbrellas to a small dog.

In montréal I've seen people just pull the turnstile back a little and then get like a foot wide gap to walk right in.

Re: Should Failing Phish Tests Be a Fireable Offense?

#189

I was just talking to a coworker yesterday and at his previous job part of his security was to go out to the employee parking lot and dump thumbdrives, if they were plugged into the corporate network they would send a message to the security department on the terminal and user account. I actually said to him, no one would be stupid enough to do that, he told me they did this monthly and at least 2 to 3 people would g…

It’s like people don’t have (private) computers anymore. If you get caught doing that, or watching animal porn on your company laptop or whatever, the problem isn’t poor IT training, the problem is that you should have bought your own computer! How are people so eager to look at the thumb drive that they can’t wait until they get home?

I could only imagine how bad things would be if most people didn’t have their own smartphones.

I think having a “guest” wifi discourages employees from using visiting random streaming websites on their work computers.

Re: Should Failing Phish Tests Be a Fireable Offense?

#190
post #44
post #32

Earlier quoted context omitted.

Often the phishing training says "do not investigate yourself" but maybe your company missed that part.

There's was the general "don't follow links in unknown emails" but nothing about what to do if you're sure it's a bad email but terminally curious. As far as I could tell nothing bad could happen (even JS was off in the browser I used to open it) when I followed the link, but is there something I should be aware of?

Curiosity killed the cat.

But you can't stop curiosity.

I wonder how many such phishing e-mails a company gets a day.

If the volume is not that high and it's something manageable by the (proper) security team, I wonder if a company could implement a policy where the employee can report a phishing e-mail to the security team and get to sit with them to watch them investigate. If that's not possible, maybe have the security team write up about investigations into phishing e-mails from time to time and send the results to employees as internal memos.

Post reply on HN